Courseiva
Iot And OT ExploitationmediumMultiple SelectObjective-mapped

CPENT Iot And OT Exploitation Practice Question

A security engineer is hardening an industrial SCADA environment against remote attacks. Which THREE of the following mitigation strategies are recommended best practices for securing OT networks? (Choose THREE)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Deploying industrial Intrusion Detection Systems (IDS) capable of parsing proprietary OT protocols (e.g., Modbus, DNP3, S7)

Securing OT networks involves strict Purdue model network segmentation, deploying unidirectional security gateways (data diodes), and implementing industrial IDS solutions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Deploying industrial Intrusion Detection Systems (IDS) capable of parsing proprietary OT protocols (e.g., Modbus, DNP3, S7)

    Why this is correct

    Industrial IDS solutions monitor for anomalous command sequences and unauthorized protocol operations on the control network.

  • Utilizing unidirectional security gateways (data diodes) where data must flow from OT to IT without permitting inbound return paths

    Why this is correct

    Data diodes physically ensure that external networks cannot send control commands or traffic back into the critical control zone.

  • Allowing unrestricted direct Internet access from all PLC controllers for automated driver updates

    Why it's wrong here

    Direct Internet access from PLCs is a severe security risk that exposes industrial controllers to direct external exploitation.

  • Disabling all encryption across SCADA servers to improve packet inspection speeds on firewalls

    Why it's wrong here

    Disabling encryption degrades security by exposing cleartext credentials and control commands to packet sniffers.

  • Implementing strict network segmentation between IT corporate networks and OT plant floors using firewalls

    Why this is correct

    Network segmentation prevents attackers who compromise the enterprise IT network from easily pivoting into the OT environment.

About these practice questions

Courseiva writes every CPENT question from scratch — 274 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official EC-Council exam blueprint

This CPENT practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CPENT exam.